SB2020022506 - Multiple vulnerabilities in D-Link DIR-867, DIR-878 and DIR-882 routers



SB2020022506 - Multiple vulnerabilities in D-Link DIR-867, DIR-878 and DIR-882 routers

Published: February 25, 2020

Security Bulletin ID SB2020022506
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Incorrect Implementation of Authentication Algorithm (CVE-ID: CVE-2020-8863)

The vulnerability allows a remote attacker to to bypass authentication process.

The vulnerability exists due to a lack of proper implementation of the authentication algorithm within the handling of HNAP PrivateLogin login requests. A remote attacker on the local network can bypass authentication and reset the admin password.

An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the router.


2) Incorrect Comparison (CVE-ID: CVE-2020-8864)

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to a lack of proper handling of empty passwords within the handling of HNAP strncmp login requests. A remote attacker on the local network can bypass authentication and reset the admin password.

An attacker can leverage this vulnerability to execute arbitrary code on the router.


Remediation

Install update from vendor's website.